Query Batching Vulnerability in Saleor E-Commerce Platform
CVE-2026-33756
7.5HIGH
What is CVE-2026-33756?
The Saleor E-Commerce Platform suffers from a resource exhaustion vulnerability due to inadequate enforcement of limits on query batching. Attackers can send a single HTTP request containing numerous GraphQL operations, circumventing the complexity limits and potentially overwhelming system resources. This issue affects versions 2.0.0 up to but not including 3.23.0a3, along with specific patch versions. Updating to the fixed versions is critical to enhance the security and stability of your e-commerce application.
Affected Version(s)
saleor >= 2.0.0, < 3.20.118 < 2.0.0, 3.20.118
saleor >= 3.21.0-a.0, < 3.21.54 < 3.21.0-a.0, 3.21.54
saleor >= 3.22.0-a.0, < 3.22.47 < 3.22.0-a.0, 3.22.47
